CVE-2026-81871

NameCVE-2026-81871
DescriptionOpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.21.0, the exporters/otlp/otlplog/otlploggrpc package loads OTEL_EXPORTER_OTLP_LOGS_CERTIFICATE, OTEL_EXPORTER_OTLP_CERTIFICATE, and related client certificate environment variables through loadEnvTLS into cfg.tlsCfg, but newGRPCDialOptions does not apply cfg.tlsCfg when creating gRPC transport credentials. The environment-only TLS path instead uses credentials.NewTLS with system roots and no configured client certificate, bypassing intended private CA pinning and mutual TLS unless the application also supplies WithTLSCredentials. A network attacker able to intercept or spoof the collector connection with a system-trusted certificate can read or alter log telemetry. This issue is fixed in version 0.21.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1149049

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-opentelemetry-otel (PTS)bookworm1.1.0-2fixed
trixie1.31.0-4vulnerable
forky1.43.0-4vulnerable
sid1.46.0-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-opentelemetry-otelsourceexperimental1.46.0-1~exp1
golang-opentelemetry-otelsourcebookworm(not affected)
golang-opentelemetry-otelsource(unstable)(unfixed)1149049

Notes

[trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
[bookworm] - golang-opentelemetry-otel <not-affected> (Vulnerable code introduced in 1.28.0)
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x
Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/d99c76fa32fbbcf3e1e0cee4c49a7f181b0697bb (v1.28.0)
Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c (v1.45.0)

Search for package or bug name: Reporting problems